[BESAdmin-Announcements] BigFix Compliance: Updated Universal Checklist for Windows Server Beta, published 2026-09-29

Announcements for BES Administrators besadmin-announcements at bigmail.bigfix.com
Tue Sep 29 09:11:21 PDT 2026


*Product: * BigFix Compliance


*Title: *Updated Universal Checklist for Windows Server (Beta) to support
more recent versions of CIS and DISA benchmarks.

*Note: The Universal Checklist for Windows Server remains in Beta. This
release updates the Beta content with the latest benchmark coverage.*

New to the Universal Checklist for Windows Server? See the original Beta
announcement here:
https://forum.bigfix.com/t/announcing-the-beta-release-universal-checklist-for-windows-server/52706


*Published Sites: * Universal Checklist for Windows Server, site version 4.
 (The site version is provided for air-gap customers.)

*Details: Universal Checklist for Windows Server (Beta)*

●       Total Fixlets: 525

●       Total New Fixlets: 17

●       Total Updated Fixlets:47

●       Total Deleted Fixlets: 0

●       Fixlets with Remediation: 510

●       Parameterized Fixlets : 378

●       Benchmark Sources: CIS and DISA STIGs

●       Applies To: Windows Server 2016, 2019, 2022, 2025

NEW FIXLETS:

●       Ensure 'Disable HTTP proxy features: Disable WPAD' is set to
'Enabled: Checked'

●       Ensure 'Enable / disable CLFS logfile authentication' is set to
'Enabled'

●       Ensure 'Disable HTTP proxy features: Disable proxy authentication'
is set to 'Enabled: Disable authentication over loopback interfaces' or
higher

●       Windows Server must be configured to audit file system failures.

●       Windows Server must be configured to audit file system successes.

●       Windows Server must be configured to audit handle manipulation
failures.

●       Windows Server must be configured to audit handle manipulation
successes.

●       Windows Server must be configured to audit registry failures.

●       Windows Server must be configured to audit registry successes.

●       Windows Server must be configured for named-based strong mappings
for certificates.

●       Ensure 'Join Microsoft MAPS' is set to 'Enabled: Advanced'

●       Ensure 'Require IPPS for IPP printers' is set to 'Enabled'

●       Ensure 'Set TLS/SSL security policy for IPP printers: Disallow
invalid certificate authority' is set to 'Enabled: Checked'

●       Ensure 'Set TLS/SSL security policy for IPP printers: Disallow
invalid certificate common name' is set to 'Enabled: Checked'

●       Ensure 'Set TLS/SSL security policy for IPP printers: Disallow
invalid certificate date' is set to 'Enabled: Checked'

●       Ensure 'Set TLS/SSL security policy for IPP printers: Disallow
non-server certificates' is set to 'Enabled: Checked'

●       Ensure 'Impersonate a client after authentication' is set to
'Administrators, LOCAL SERVICE, NETWORK SERVICE, SERVICE, RESTRICTED
SERVICES\PrintSpoolerService'







UPDATED FIXLETS:

●       Ensure 'Interactive logon: Do not require CTRL+ALT+DEL' is set to
'Disabled'

●       Ensure 'Windows Firewall: Domain: Logging: Name' is configured

●       Ensure 'Windows Firewall: Private: Logging: Name' is configured

●       Ensure 'Windows Firewall: Public: Logging: Name' is configured

●       Ensure 'Limit Diagnostic Log Collection' is set to 'Enabled'

●       Ensure 'Limit Dump Collection' is set to 'Enabled'

●       Ensure 'Enable OneSettings Auditing' is set to 'Enabled'

●       Ensure 'Set time limit for active but idle Remote Desktop Services
sessions' is set to 'Enabled: 15 minutes or less, but not Never (0)'

●       Configure 'Accounts: Rename guest account'

●       Configure 'Accounts: Rename administrator account'

●       Ensure 'Account lockout duration' is set to '15 or more minute(s)'

●       Ensure 'Configure validation of ROCA-vulnerable WHfB keys during
authentication' is set to 'Enabled: Block' (DC only)

●       Ensure 'Post-authentication actions: Actions' is set to 'Enabled:
Reset the password and logoff the managed account' or higher

●       Ensure 'Password Settings: Password Complexity' is set to 'Enabled:
Large letters + small letters + numbers + special characters' or
'Passphrase'

●       Ensure 'Prevent automatic download of applications associated with
device metadata' is set to 'Enabled'

●       Ensure Deny log on as a service user right on domain-joined member
servers must be configured to prevent access from highly privileged domain
accounts. No other groups or accounts must be assigned this right.

●       Ensure Deny log on as a batch job user right on domain-joined
member servers must be configured to prevent access from highly privileged
domain accounts and from unauthenticated access on all systems.

●       Ensure 'Enable Certificate Padding' is set to 'Enabled'

●       Ensure 'Reset account lockout counter after' is set to '15 or more
minute(s)'

●       Ensure 'Toggle user control over Insider builds' is set to
'Disabled'

●       Ensure 'Turn off Microsoft Defender AntiVirus' is set to 'Disabled'

●       Ensure 'Change the time zone' is set to 'Administrators, LOCAL
SERVICE'

●       Ensure 'MSS: (ScreenSaverGracePeriod) The time in seconds before
the screen saver grace period expires' is set to 'Enabled: 5 or fewer
seconds'

●       Ensure 'Configure registry policy processing: Do not apply during
periodic background processing' is set to 'Enabled: FALSE'

●       Ensure 'Turn off picture password sign-in' is set to 'Enabled'

●       Ensure 'Turn off Microsoft consumer experiences' is set to 'Enabled'

●       Ensure 'Disable OneSettings Downloads' is set to 'Enabled'

●       Ensure 'Join Microsoft MAPS' is set to 'Disabled'

●       Ensure 'Configure local setting override for reporting to Microsoft
MAPS' is set to 'Disabled'

●       Ensure 'Configure Attack Surface Reduction rules' is set to
'Enabled'

●       Ensure 'Configure Attack Surface Reduction rules: Set the state for
each ASR rule' is configured

●       Ensure 'Prevent users and apps from accessing dangerous websites'
is set to 'Enabled: Block'

●       Ensure 'Enable file hash computation feature' is set to 'Enabled'

●       Ensure 'Scan all downloaded files and attachments' is set to
'Enabled'

●       Ensure 'Turn off real-time protection' is set to 'Disabled'

●       Ensure 'Turn on script scanning' is set to 'Enabled'

●       Ensure 'Configure Watson events' is set to 'Disabled'

●       Ensure 'Scan packed executables' is set to 'Enabled'

●       Ensure 'Scan removable drives' is set to 'Enabled'

●       Ensure 'Turn on e-mail scanning' is set to 'Enabled'

●       Ensure 'Configure detection for potentially unwanted applications'
is set to 'Enabled: Block'

●       Ensure 'Allow Custom SSPs and APs to be loaded into LSASS' is set
to 'Disabled'

●       Ensure 'WDigest Authentication' is set to 'Disabled'

●       Ensure 'Network security: Do not store LAN Manager hash value on
next password change' is set to 'Enabled'

●       Ensure 'Do not allow WebAuthn redirection' is set to 'Enabled'

●       Ensure 'Prevent device metadata retrieval from the Internet' is set
to 'Enabled'

●       Ensure impersonate a client after authentication user right must
only be assigned to Administrators, Service, Local Service, and Network
Service.



*Actions to take:*

●       To subscribe to the above site, you can use the License Overview
Dashboard to enable and gather the site. Note that you must be entitled to
the BigFix Compliance product, and you must be using BigFix version 10 and
later.

●       If you use custom sites, update your custom sites accordingly to
use the latest content. You can synchronize your content by using the
Synchronize Custom Checks wizard. For more information, see
<https://help.hcltechsw.com/bigfix/11.0/compliance/Compliance/SCM_Users_Guide/c_using_synchronize_custom_checks_wiz.html>Using
the Synchronize Custom Checks wizard
<https://help.hcltechsw.com/bigfix/11.0/compliance/Compliance/SCM_Users_Guide/c_using_synchronize_custom_checks_wiz.html>
.


*More information: * To know more about the BigFix Compliance SCM
checklists, please see the following resources:

●       BigFix Forum:
<https://forum.bigfix.com/c/release-announcements/compliance>
https://forum.bigfix.com/c/release-announcements/compliance

●       BigFix Compliance SCM Checklists:
<https://forum.bigfix.com/t/universal-compliance-checklist/54703>
https://forum.bigfix.com/t/universal-compliance-checklist/54703

We hope you find this latest release of SCM content useful and effective.
Thank you.

*– The BigFix Compliance team*
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://bigmail.bigfix.com/pipermail/besadmin-announcements/attachments/20260929/a18cdf2d/attachment.html>


More information about the Besadmin-announcements mailing list